LOWVulnerability
Global

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

·Source: Qualys Blog

Updated:

Executive Summary

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox […]

Analysis

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox […]

Indicators of Compromise (1)

CVE (1)
CVE-2026-8933
Source Attribution

Originally published by Qualys Blog on Jul 21, 2026.

Related Threats

LOWVulnerability

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a

Krebs on Security
MEDIUMVulnerability

Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack

Milford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email alerts, shared with DataBreaches by a town resident, reveal... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-60210 — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo...

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

CVE-2026-60210
NIST NVD